Were you recently affected by a data breach?

SportsMed Physical Therapy Data Breach

SportsMed Physical Therapy, a New Jersey outpatient rehabilitation provider, discovered a compromised employee email account exposing patient names, treatment details, and health insurance information. Affected patients may be entitled to compensation.

SportsMed Physical Therapy
Date of Breach: May 8, 2026
CAU logo

Who was affected:

Clients of SportsMed Physical Therapy

Impacted Data:

Patient names, dates of service, provider names, diagnosis information, treatment information, health insurance information

SportsMed Physical Therapy, a multidisciplinary outpatient rehabilitation provider headquartered in Glen Rock, New Jersey, has notified patients of a data security incident involving a compromised employee email account. The exposed data may include sensitive health and treatment information tied to specific patients. Companies that store medical and personal information have a responsibility to keep it secure, and when that trust is broken, patients deserve clear answers.

SportsMed Physical Therapy’s Data Breach Investigation

On May 8, 2026, SportsMed Physical Therapy detected suspicious activity connected to a single employee email account and launched an investigation into the incident. The company has stated that the investigation into the matter is ongoing, and it has not disclosed a specific root cause beyond describing the incident as unauthorized access to an employee’s email account, sometimes referred to as a business email compromise.

According to the company’s public notice, the information that may have been contained within the affected email account includes patient names along with one or more of the following: dates of service, provider names, diagnosis information, treatment information, and health insurance information. SportsMed Physical Therapy has said that, at this time, there is no indication that any of this information has actually been misused, though it continues to monitor the situation.

Email-based breaches like this one are increasingly common across the healthcare industry, in part because a single compromised inbox can contain months or years of accumulated patient correspondence, referral letters, billing documents, and clinical notes. Unlike a breach of a structured database, an email account compromise can expose a wide and unpredictable range of information, since employees routinely receive and send sensitive records as part of normal business operations. This makes it harder for an organization to quickly and precisely determine the full scope of what was exposed.

The combination of data types SportsMed Physical Therapy has flagged as potentially involved, patient names paired with treatment and diagnosis information, is particularly valuable to bad actors because it can be used for medical identity theft, fraudulent insurance claims, or targeted phishing schemes that reference real appointment dates or providers to appear more legitimate. Even without Social Security numbers or financial account details being confirmed as exposed, health information alone can be misused in ways that are difficult for victims to detect quickly, since fraudulent insurance activity or medical billing often surfaces only when a patient reviews an explanation of benefits or receives an unexpected bill.

Healthcare providers are generally required under laws like HIPAA to safeguard protected health information and to notify affected individuals when a breach involving that information occurs. SportsMed Physical Therapy’s decision to reset passwords and review its internal policies and procedures following the incident reflects standard remediation steps for this type of email compromise, though the company has not detailed what additional technical safeguards, if any, it plans to implement to prevent a similar incident going forward.

Individuals who received notice from SportsMed Physical Therapy, or who believe they may have been a patient during the relevant time period, should carefully review any communication from the company and remain alert to signs that their information has been misused, including unfamiliar medical bills, unexpected insurance claims, or suspicious account activity.

Physical therapy and outpatient rehabilitation practices, like many smaller healthcare providers, are frequently targeted by cybercriminals precisely because they may lack the extensive cybersecurity resources of larger hospital systems while still maintaining large volumes of sensitive patient records. A single employee’s inbox at a multi-location practice can accumulate years of referral correspondence, appointment scheduling details, and treatment notes, making it an attractive target for attackers seeking to harvest personal and health information in bulk rather than having to breach a more heavily defended central database.

The notification timeline in this case, roughly two months between the May 8, 2026 detection date and the July 7, 2026 public notice, is not unusual for incidents involving email account compromises, where organizations often need time to review the full contents of an affected mailbox before they can determine which specific patients and data elements were involved. State and federal breach notification laws generally set outer deadlines for notifying affected individuals, but the exact time required to complete a thorough email review can vary significantly depending on the volume of messages and the complexity of the investigation.

When Did This Breach Occur?

SportsMed Physical Therapy detected the suspicious email account activity on May 8, 2026, and began an investigation shortly afterward. The company posted a notice on its website on July 7, 2026, informing patients of the incident. SportsMed Physical Therapy has not disclosed an exact date on which the unauthorized access began, only that it discovered the activity on May 8, 2026, and that its investigation into the full timeline remains ongoing.

What Information Was Breached?

According to SportsMed Physical Therapy’s notice, the information that may have been contained within the compromised email account includes patient names along with one or more of the following: dates of service, provider names, diagnosis information, treatment information, and health insurance information. The company has not specified exactly how many patients were affected or which specific combination of these data types applies to any individual patient.

What You Can Do

If you received a notice from SportsMed Physical Therapy, review it carefully to understand what information about you may have been involved. Regularly review your health insurance explanation of benefits statements and medical bills for services you did not receive, which can be a sign of medical identity theft. You may also want to monitor your credit reports and account statements for unfamiliar activity. Under federal law, you are entitled to one free credit report annually from each of the three major credit bureaus at annualcreditreport.com. If you have questions, SportsMed Physical Therapy has set up a dedicated call center at 1-833-851-9744.

File a Data Breach Lawsuit Against SportsMed Physical Therapy

If you were notified that your personal or health information may have been exposed in the SportsMed Physical Therapy data breach, you may have legal options available to you. Individuals affected by healthcare data breaches can face real and lasting consequences, from the time spent monitoring accounts to the anxiety of not knowing how their sensitive medical information might be used.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: May 8, 2026
Date of Breach: January 28, 2026
Date of Breach: Not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.